Page 4 of 4 FirstFirst 1234
Results 31 to 37 of 37
  1. #31
    Join Date
    Dec 2004
    Location
    Nottingham
    Posts
    7,571
    Tokens
    2,674

    Latest Awards:

    Default

    I think an announcement should be made as a warning, and explaining exactly what it is, how it works and how to avoid it. Because I have no idea, and judging from this thread most other people dont either

  2. #32
    Join Date
    Mar 2005
    Posts
    1,196
    Tokens
    1,596

    Latest Awards:

    Default

    There's a lot of 'session stealer' sites around this second and they are VERY VERY dangerous.

    basically they encode something into the habbo credits page (via a variable exploit) which sends the information about your habbo account (typically the session id) which can be used to gain control of your account.

    So don't click any links that you aren't 100% secure with clicking at all. If you find yourself maliciously redirected to one of these sites you might not even realise. If you've got doubts right click and see if there's anything to do with a habbo credits page in the source. If there is; leave it and change your pass and email and email pass IMMEDIATELY.

    This exploit is active on ALL hotels currently.

    Habbox has to
    filter these terms: ********* - *********

    so it doesnt happen to Habbox
    Last edited by beau03; 03-06-2007 at 08:41 PM.
    If your actions inspire others to dream more,
    learn more, do more and become more,
    you are a leader.

    Habbo eXpert

  3. #33
    Join Date
    Mar 2007
    Location
    Kent
    Posts
    11,415
    Tokens
    787

    Latest Awards:

    Default

    just filter them words as shown above & the most common host till the whole tihng gets boring [:

    =]

  4. #34
    Join Date
    Aug 2004
    Location
    USA
    Posts
    4,518
    Tokens
    3,536
    Habbo
    nvrspk4

    Latest Awards:

    Default

    I've put an announcement up: http://www.habboxforum.com/showthrea...07#post3565207

    Tell me if you think anything should be added, preferrably by PM as I'll see it first

    We are also looking into filtering *********, *********, and www.tinyurl.com (only the whole site so people can warn others about the site itself).

    Thanks!
    Last edited by nvrspk4; 04-06-2007 at 03:50 AM.
    It costs nothing to be a good friend.

    American and Proud

    I also use the account nvrspk on other computers.


  5. #35
    Join Date
    Aug 2004
    Location
    UK
    Posts
    11,283
    Tokens
    2,031

    Latest Awards:

    Default

    Im slightly confused what people are on about? If its on the habbo page then the problem is probably XSS vunrabilty? and thats habbos fault for designing there webpage crapily, not habboxs or another fan site.

  6. #36
    Join Date
    Jan 2007
    Posts
    7,652
    Tokens
    0

    Latest Awards:

    Default

    i was lucky. i went on a session stealer, that was posted in the advertise my site here, but i was not on Habbo and did not log in to it ect.
    i don't realy understand what they do, someone explain?

  7. #37
    Join Date
    Mar 2005
    Posts
    1,196
    Tokens
    1,596

    Latest Awards:

    Default

    TO REMOVE:

    Internet Explorer:

    1. LOG OUT of Habbo
    2. Tools
    3. Internet Options
    4. Delete Cookies


    Mozilla Firefox

    1. Tools (Edit on a Mac)
    2. Options
    3. Privacy icon
    4. Show Cookies
    5. Remove All Cookies


    Good Luck!
    If your actions inspire others to dream more,
    learn more, do more and become more,
    you are a leader.

    Habbo eXpert

Page 4 of 4 FirstFirst 1234

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •